Keyfactor Tech Days 2027, The Trust Security Conference, is heading to San Diego!   Discover what’s coming up

  • Home
  • Blog
  • PKI
  • How to Set Up PKI Infrastructure: A Planning Guide

How to Set Up PKI Infrastructure: A Planning Guide

PKI

Whether you’re securing cloud workloads, embedding identities into connected products, or protecting internal applications, public key infrastructure (PKI) has become the foundation of digital trust for modern organizations. Over the last two decades, PKI has evolved from a fringe technology into a ubiquitous piece of infrastructure used by virtually every team in IT.

But here’s the thing: setting up PKI infrastructure that actually works for your organization requires more than installing certificate authority (CA) software. It requires careful planning, the right expertise, and a clear understanding of your needs today and where they’re headed tomorrow.

Start by mapping your PKI use cases

Before you deploy anything, you need to understand what your PKI will actually support. Modern enterprises use certificates for everything from securing web servers and authenticating users to protecting IoT devices and signing code. Each use case requires different certificate types, templates, protocols, and automation capabilities.

Getting this wrong means you’ll either over-engineer your PKI or find yourself scrambling to bolt on capabilities later. That’s why the first planning step is simple:

  • document which teams and applications need certificates,
  • what protocols they actually require (ACME, SCEP, EST, CMP, REST API),
  • how many certificates you expect to issue annually, and
  • how those numbers are likely to grow.

This exercise prevents the most common planning mistake: building PKI for today’s needs rather than tomorrow’s.

Evaluate your team’s PKI expertise and resources

PKI requires specialized knowledge that most IT teams simply don’t have on staff. Only about 50% of companies have enough staff dedicated to their PKI deployment. That means more than half of organizations are running critical security infrastructure without adequate resources to manage it.

PKI has always been something of a technical “hot potato.” It gets passed between different teams or individuals without any clear ownership, and when an incident like a certificate outage occurs, it’s difficult to respond effectively. For several organizations, there is no clear owner of the PKI at all, a problem that spans industries and verticals.

This matters because PKI isn’t a set-it-and-forget-it technology. It is critical infrastructure with a lifespan of up to 25 years. Someone needs to own it: designing certificate policies, managing key ceremonies, monitoring for expiring certificates, and adapting the infrastructure as use cases evolve.

Ask yourself honestly: Does your team have the expertise and bandwidth to set up and run a robust PKI over its entire lifespan? If the answer is no, that’s not a failure. It’s a signal to consider working with a managed service provider or trusted partner who can handle the operational burden while your team focuses on core business objectives.

PKI is more than just CA software and certificates. You’ll also need to consider the safeguards and policies around your PKI infrastructure to meet expected assurance levels and protect the private keys behind your root of trust.

Integrate your policies into the design

Speaking about policy, setting up a PKI is a policy exercise before a technical one, because every operational decision flows from one question: what does a certificate from this CA mean, and what does it guarantee? That intent is formalized in a Certificate Policy (the rules a certificate asserts) and a Certification Practice Statement (how the CA operates to meet them), conventionally structured on the RFC 3647 framework. From there, the core decisions divide into a handful of areas:

  • the trust architecture: how many tiers, one root or several, and above all public versus private trust;
  • the certificate profiles: key algorithms and sizes, validity periods, and permitted usages, now including post-quantum and hybrid options;
  • key management: HSM protection levels, witnessed generation ceremonies under m-of-n control, and strict rules on backup and escrow, since the CA’s private keys are the entire trust anchor;
  • identity and registration: what proof is required before issuance and which enrollment protocols are permitted; and
  • the revocation regime: what triggers revocation and how quickly status reaches relying parties.

Wrapping those are the operational and compliance controls that make the policy credible: physical and logical security, role-based access with enforced separation of duties, tamper-evident audit logging, disaster recovery, and the applicable regulatory, audit, and data-residency requirements, the last of which directly shapes the cloud-versus-on-prem deployment choice. The through-line is that the Certificate Policy is the contract, and every control exists to make that contract credible and auditable. Crypto-agility now belongs in that contract as a policy dimension in its own right: the CP should state how new algorithms are approved into profiles and how transitions like the PQC migration are governed, so that agility is a written, auditable property rather than an ad-hoc reaction.

Choose the right PKI deployment model

Here’s a breakdown of the available models:

Cloud-based PKI: Hosted infrastructure that delivers certificates to cloud workloads and distributed environments. This model offers faster deployment, automatic scaling, and lower operational overhead. This model is ideal for organizations with cloud-first strategies or limited in-house PKI expertise.

On-premise PKI: Traditional infrastructure deployed within your data center, giving you complete control over hardware, policies, and data residency. This model suits organizations with strict compliance requirements or existing investments in on-prem infrastructure.

Hybrid PKI: A combination approach where cloud-based PKI serves cloud workloads while on-prem infrastructure handles legacy systems and internal resources. This is increasingly the default for modern enterprises that need flexibility without managing separate systems.

PKI as a Service (PKIaaS): A fully managed offering in which a provider operates your CA while you retain policy control and consume issuance through APIs. It shares cloud-based PKI’s fast deployment and low operational overhead; the difference is that PKIaaS defines the operating model rather than merely where the PKI runs. This suits organizations that want a private, compliant trust anchor without the burden, or the specialized expertise, of running a CA in-house.

The critical question isn’t “cloud or on-prem?” But rather, it is “which workloads need certificates from where?” Applications that have moved to the cloud should get their certificates from cloud-based PKI. On-prem resources should continue getting certificates from on-prem infrastructure. A modern PKI solution gives you the flexibility to do both without managing separate systems.

Making intelligent design decisions for your PKI

Scalability and availability aren’t features you can bolt on later. They need to be designed into your PKI from the start.

One of the most common problems in enterprise PKI is what’s known as “shadow PKI.” Different teams deploy their own certificate authorities for specific use cases without considering corporate IT policies. CAs get misconfigured. Certificates go untracked. The result: unexpected audit findings, security gaps, and outages nobody saw coming.

Consolidation doesn’t mean forcing everything onto a single CA. It means using one platform that can logically separate multiple CA hierarchies and tenants while maintaining a unified view. You can still have distinct CAs for different business units or use cases; they just run on the same infrastructure under the same governance framework.

Managing the lifecycle of your certificates

Issuing certificates is only the beginning. After that, they need to be managed, and that’s where most organizations struggle.

The most effective approach combines PKI and certificate lifecycle management into a single platform. This way, you’re not just issuing certificates; you’re managing and automating their entire lifecycle from a single pane of glass. You maintain the flexibility to manage certificates across all CAs in your environment, including cloud-native or publicly trusted CA vendors that sit outside your primary PKI.

How to set up PKI infrastructure with Keyfactor

Setting up PKI infrastructure doesn’t have to be overwhelming. Here’s how to approach it systematically, and where Keyfactor’s platform fits into each step:

Step 1: Deploy your certificate authorities
Start by establishing your CA hierarchy, whether that’s a single-tier setup for simpler environments or a multi-tier architecture with root and issuing CAs for enterprise-grade security. Keyfactor EJBCA gives you the flexibility to deploy CAs in the cloud, on-premises, or in a hybrid configuration. It’s built on open standards and supports every major protocol (ACME, SCEP, EST, CMP, REST API), so you’re not locked into proprietary systems or limited in how you issue certificates.

Step 2: Establish governance and certificate policies
Define who can request certificates, what types of certificates can be issued, and under what conditions. EJBCA lets you configure certificate profiles, end entity profiles, and approval workflows that enforce your security policies at the CA level. This ensures consistency and compliance across every certificate you issue, regardless of which team or application is requesting it.

Step 3: Integrate with your existing infrastructure
Your PKI needs to work with the tools and platforms your teams already use. EJBCA integrates natively with Microsoft environments (Active Directory, Intune, Azure Key Vault), Kubernetes clusters, cloud platforms, and DevOps pipelines. This means developers and IT teams can request and renew certificates using the workflows they’re already familiar with.

Step 4: Gain visibility across your entire certificate estate
Once certificates start flowing, you need a way to track them, not just from your new PKI, but from every CA in your environment. Keyfactor Command provides a unified certificate lifecycle management platform that discovers, inventories, and monitors certificates across all sources: your internal CAs, public CAs, cloud-native services, and even shadow IT. You get a single pane of glass for every certificate in your organization, regardless of where it came from.

Step 5: Automate certificate lifecycle operations
Manual certificate management doesn’t scale. Command automates enrollment, renewal, revocation, and deployment across your infrastructure. It integrates with load balancers, web servers, cloud platforms, and container orchestration systems to ensure certificates are always up to date without manual intervention. As certificate lifespans continue to shrink, this automation becomes essential to preventing outages.

Step 6: Extend PKI to connected products and devices
If you’re embedding certificates into IoT devices, connected products, or distributed edge infrastructure, you need a solution built for scale and zero-touch provisioning. Keyfactor AgileSec is purpose-built for product and device identity, handling certificate injection during manufacturing, over-the-air updates, and lifecycle management for millions of devices. It bridges the gap between traditional enterprise PKI and the unique demands of product security.

Got PKI infrastructure questions? We’ve got answers.

Q: What are the core components of a PKI infrastructure?
A PKI infrastructure consists of certificate authorities (CAs) that issue and manage digital certificates, registration authorities (RAs) that verify certificate requests, and validation authorities (VAs) that check certificate status. Supporting components include hardware security modules (HSMs) to protect private keys, CRL or OCSP responders for real-time validation, and a certificate management platform for visibility and automation.

Q: Should I deploy PKI in the cloud or on-premises?
It depends on your regulatory requirements, available expertise, and infrastructure strategy. Cloud and SaaS PKI options offer faster deployment and lower maintenance overhead. On-premises deployments suit organizations with strict data residency or compliance requirements. Many organizations choose a hybrid approach, issuing certificates from cloud-based PKI for cloud workloads and maintaining on-prem PKI for legacy systems.

Q: How do I decide between public and private PKI?
Use public trust for internet-facing applications where any browser or device needs to verify your certificates (websites, SaaS applications). Use private PKI for internal systems, IoT devices, and products where you control the endpoints and can manage the trust chain yourself. Many organizations use a combination of both.

Q: What is PKI as a Service (PKIaaS)?
PKIaaS is a fully managed PKI deployment where a trusted provider handles the infrastructure, monitoring, maintenance, and updates. You consume certificates without needing to manage the underlying CA infrastructure. This model reduces the need for in-house PKI expertise and ensures your PKI follows best practices with guaranteed uptime SLAs.

Q: How many certificate authorities does a typical enterprise need?
It varies, but organizations without a consolidation strategy often end up with nine or more disparate PKI systems. Modern PKI platforms allow you to consolidate multiple CA hierarchies onto a single platform, reducing complexity and cost while maintaining logical separation for different business units or use cases.

Q: What skills does my team need to manage PKI?
PKI requires expertise in cryptography, certificate management, security policy design, and infrastructure operations. According to the 2023 State of Machine Identity Management report, more than half of organizations say they do not have enough staff dedicated to PKI. If your team lacks these skills, consider a managed or SaaS PKI service to offload the operational burden.

Q: How do I prevent certificate outages after setting up PKI?
Combine your PKI with certificate lifecycle automation that provides visibility across all certificate authorities, automated renewal and provisioning, and alerting before certificates expire. As certificate volumes grow and lifespans shorten, manual tracking methods become unsustainable.

Q: Can I run my new PKI alongside my existing Microsoft CA?
Yes. Modern PKI solutions can run in tandem with Microsoft CA, supporting Microsoft-native tools like Auto-enrollment, Intune, and Azure Key Vault while also handling modern use cases. This allows you to migrate at your own pace rather than requiring a disruptive cutover.